SCS-C02 Threat Detection and Incident Response • Set 15
SCS-C02 Threat Detection and Incident Response Practice Test 15 — 15 questions with explanations. Free, no signup.
A company uses AWS CloudTrail to log all API activity. The security team wants to ensure that any changes to CloudTrail configuration (e.g., disabling the trail, deleting the trail, modifying the log delivery) are detected immediately. They have created a CloudWatch Events rule to capture the event 'StopLogging' and send an SNS notification. During testing, the team stops the trail and does not receive the notification. The CloudWatch Events rule is configured with the correct event pattern. What should the team check?
Choose an answer to begin — your selection is scored in the full session.
15 questions · instant feedback and full explanations after every question.